Week of September 21 -- 27, 2026
The grove→project rename reached its breaking phase this week. Legacy grove routes, CLI flags, API keys, event topics, container labels, environment variables and hub↔broker wire fields were all removed, and on-disk grove state now migrates automatically. Hub and broker must now be upgraded together. Alongside the rename, a broad authorization sweep closed several cross-member and cross-project exposure paths. Single-node VM deployment became headless, self-updating and Vertex-ready out of the box, and the new persistent terminal workspace gained shareable layouts and auto-reconnect.
Highlights
Section titled “Highlights”1. Grove → Project Rename Completes
Section titled “1. Grove → Project Rename Completes”Over three days the remaining grove aliases were removed from every layer. That covers /api/v1/groves routes, --grove flags, scion grove commands, groveId-style request and response keys, scion.grove.* topics, scion.grove* container labels, SCION_GROVE* agent env vars, and the hub↔broker HTTP, heartbeat and websocket protocols. On startup, the CLI, hub and broker move ~/.scion/groves and ~/.scion/grove-configs to their project equivalents, leaving symlinks behind. They also rewrite .scion/grove-id and hub.grove_id in place. Hub and broker versions can no longer be mixed, and agents created before the rename should be restarted. The new grove removal migration guide lists every change and its replacement.
2. Authorization and Isolation Hardening
Section titled “2. Authorization and Isolation Hardening”A wide security sweep closed several exposure paths. Project owners and admins could attach to members’ agents and read their user-scoped secrets; agent.lifecycle is now split from agent.attach to stop this. Duplicate legacy grove.<projectId>.* SSE subjects let any authenticated session read every project’s live events; they are removed, and SSE authorization now uses a deny-by-default allowlist. Six template handlers had no authorization checks, and broker agent delete could remove a same-slug agent in another project. Both are fixed. Resource, workspace, agent and broker-ownership routes now authorize at a single dispatcher, and user- and project-scoped skills, templates and harness configs are readable only within their scope. Project file handlers and attachment ingest now use os.Root to block symlink traversal.
3. Single-Node VM Deployment Grows Up
Section titled “3. Single-Node VM Deployment Grows Up”The single-node VM tier gained binary auto-update. The Hub now checks for updates according to a configured deployment tier, release channel and update policy, using LATEST.json and GitHub Releases for binary installs. deploy.sh --config pre-answers every wizard prompt, which enables agent-driven, non-interactive installs from a new agent deployment runbook. It also works in hardened GCP orgs (no default VPC, Shielded VM required, default compute SA disabled). A hub-wide default GCP identity (block, passthrough or assign) means a fresh VM can run Vertex AI inference without manual setup.
4. Persistent Terminal Workspace
Section titled “4. Persistent Terminal Workspace”A multi-pane terminal workspace landed behind the terminal_workspace feature flag (off by default). It supports cross-tab ownership, reconnect controls and scoped PTY cleanup. Layouts are encoded in the URL, so multi-pane configurations can be shared and bookmarked. A new PTY close-code contract tells a clean detach apart from an ended session, a missing agent or a retriable drop. Together with keepalive pings, this lets panes reconnect automatically behind a “Reconnecting…” overlay.
⚠️ Breaking Changes
Section titled “⚠️ Breaking Changes”- Hub and broker must be upgraded together (#2015, #2017): Grove-named fields are removed from hub↔broker wire types, the heartbeat payload and the broker websocket protocol.
/api/v1/workspace/grove-uploadis replaced by/api/v1/workspace/project-upload. - Hub API grove keys removed (#1999, #1997, #1958, #1968, #1944):
/api/v1/groves[/…]returns 404. Requests and responses no longer carrygroveId,groveName,groveorgroves, including in SSE payloads and store models."grove"is rejected as a scope with 400. Resolved secrets reportsource: "project". Existingscope='grove'rows are normalized on boot. - Grove CLI commands, flags and output keys removed (#1938, #1957, #1954, #1960, #1961, #1971):
scion grove,scion hub groves,scion config cd-grove, every--groveflag, thegrove:template-scope prefix andgrove_idconfig keys are gone.--jsonoutput emits onlyproject*keys. - Grove topics, labels and env vars dropped (#2001, #2012, #1995, #2016, #1962): Only
scion.project.*topics are routed, and containers carry onlyscion.project*labels. Agents no longer receive or readSCION_GROVE_ID,SCION_GROVEorSCION_GROVE_PATH, andSCION_HUB_GROVE_IDis ignored. Setting a legacy variable prints a one-time warning. Restart agents created before the rename. - a2a-bridge and fs-watcher grove aliases removed (#1990): The a2a-bridge silently ignores a
groves:config key, so a config that uses onlygroves:starts with zero projects. Rename it toprojects:. - Agent permission model split (#1838):
agent.lifecycle(start/stop/suspend/restart/restore) is separated fromagent.attach. Project owners and admins keep lifecycle and messaging rights on members’ agents but loseattachandport_access. Project-owner and project-admin roles move to revision 3. - Per-broker agent limit (#1902, #1946):
max_agents_per_broker(default 12, overridable per broker) is checked before agent creation. Previously, creating agents past capacity could crash the broker host. Only running agents count toward the limit. - GCP
--projectrenamed to--gcp-project(#1937): Applies toscion project service-accounts addandscion hub secret migrate. There is no alias, but old invocations print a targeted hint. visibilityfield removed (#1916, #1929): The field is gone from agents, templates, harness configs and skills. Access depends only on scope and grants.- Broker error code renamed (#1923):
global_grove_disabledis nowglobal_project_disabled. - Copilot and grok-build telemetry env reserved (#2018): Agents fail to start if the runtime env overrides
COPILOT_OTEL_*,GROK_TELEMETRY_*orGROK_EXTERNAL_OTEL.
🔐 Security & Access Control
Section titled “🔐 Security & Access Control”- Cross-project SSE leak closed (#1970, #1809): Legacy grove publish subjects are removed, SSE authorization uses an explicit allowlist, and
project.>wildcard subscriptions expand only to projects the caller is authorized for. - Cross-member secret exposure (#1838): Owners and admins can no longer attach, exec, read env or reach ports on other members’ agents.
- Template authorization (#1804, #1881): Six template handlers gained missing
authorize()gates. Before this, any authenticated user could modify any template, including global ones. The template files subtree now checks access on the specific template and validates paths. - Hub route authorization (#1886, #1882, #1926): Agent status, harness config, project GitHub settings, project workspace (files, archive, WebDAV, sync) and project agent routes now authorize once in a dispatcher. Chat search returns DM threads only to their participants.
- Scope boundary on resource reads (#1912, #1936): User- and project-scoped skills, templates and harness configs are readable only by their owner, project members and hub admins. Template resolution and cloning are scope-checked.
- Cross-project agent delete (#1875): Broker delete is scoped to the requested project on every runtime and fails closed on ambiguous matches.
- Symlink traversal hardening (#1850, #1876): Project file handlers and attachment ingest resolve paths through
os.Root, so symlinks that point outside the served directory are refused. - Broker ownership and project updates (#1982, #1969, #1949, #1945): Broker re-registration and secret rotation require broker ownership. Implicit project mutations (register, provider link, auto-link) require update access.
- Harness telemetry redaction bypass (#2018): Copilot and grok-build now always export OTel through the local sciontool receiver, so redaction and identity stamping apply.
- Credential handling (#1894, #1966, #1942, #1870): The
reset-authtoken is passed over stdin instead of argv. The transport service account is never provisioned as a hub user. GitHub webhooks are rejected when no secret is configured. Broker failure reasons are sanitized and truncated to 512 bytes. - Skill download capability URLs (#1874): Local-storage Hubs issue 15-minute HMAC-signed URLs bound to the exact skill, version and path, which fixes 401s on broker skill downloads.
- Global skill authoring permission (#1803, #1807): The new
skill.create_globalpermission andglobal-catalog-authorrole allow global catalog writes without full hub-admin authority. - Path and network hardening (#1998, #1979): Agent names are validated as single clean path elements. The single-node VM’s IAP SSH firewall rule targets only the hub VM.
🔑 Authentication & Identity
Section titled “🔑 Authentication & Identity”- Generic JWT proxy auth provider (#1858, #1863):
auth.proxy.provider: jwtsupports bespoke auth proxies. Keys can come from PEM files, a JWKS URL (with proactive refresh and last-good fallback) or a JWKS file, with issuer/audience validation and OIDC claim mapping. - Google bearer pass-through for A2A (#1880): The Hub accepts Google ID tokens and OAuth access tokens directly, with per-issuer trust settings. The A2A bridge gains a
hubBearerscheme. The GE token exchange is deprecated. - Hub-default GCP identity (#1906, #1927, #1915, #1899, #1897, #1883): Agent Defaults gains a hub-wide GCP identity mode, which also applies to scheduled dispatch. Single-node VMs default to passthrough and seed Vertex AI env vars.
- Scheduled agent identity (#1872): Scheduled agents get
CreatorNameand the project-default GCP identity, subject to the same checks as manual creation.
🖥️ Terminal Workspace
Section titled “🖥️ Terminal Workspace”- Persistent terminal workspace (#1795): Multi-pane workspace with cross-tab ownership, reconnect controls and scoped PTY cleanup, behind the
terminal_workspaceflag. - Auto-reconnect (#1953, #1973, #1984, #1959, #1993): The PTY close-code contract (1000, 4410, 4404, 4503), broker-side classification of why each attach ended, keepalive pings and a single reconnect attempt when the pane is next in front.
- URL layout encoding (#1816): Multi-pane layouts persist in the URL, so they can be shared and bookmarked.
- Layout and theming fixes (#1805, #1812, #1806, #2011): Layouts are preserved during navigation. Stale focus outlines are removed. Tmux titles sync on attach. The terminal pane now follows light-mode theme tokens.
💬 Chat & Messaging
Section titled “💬 Chat & Messaging”- Honest message delivery (#1868, #1895, #1893, #1892, #1940, #1903): Messages to non-running agents fail with “Agent unreachable” or
DELIVERY_FAILEDinstead of showing “Delivered”. Broker flush failures are retried three times and reported to senders live. Failed messages are purged after 7 days. - Cross-project messaging cleanup (#1808): A 4-phase pass covering admission-gap authorization, truthful delivery, a converged send API and acceptance tests.
- Group conversations (#1846, #1864): CLI-created groups appear in web chat. The default agent is kept consistent across both stores, and agents dispatched into a group are tracked as participants.
- Browser notification chime (#1861): A two-tone chime plays when messages from other users arrive, with global and per-project toggles.
- Chat navigation (#1932, #1911, #1910, #1871): Threads with unreads open at the “New messages” divider. Inter-agent messages get day dividers and a two-line layout. The thread-default agent is listed first.
- Touch and mobile (#1857, #1859): On touch devices, Enter inserts a newline, and the message context menu opens on tap.
- Chat fixes (#1794, #1826, #1829, #1913, #1921, #1939, #1855, #1856): File-path auto-linking and resolution fixes, one-keystroke @mention deletion, fixed promote-DM-to-thread errors, and an end to members-sidebar flicker.
🤖 Agent Lifecycle
Section titled “🤖 Agent Lifecycle”scion reincarnate(#1918): Restarts an agent on the same row with a freshly derived config, image and harness config, through an async hub worker with dry-run support.- Best-effort resume (#1900):
forceResumeand a “Resume (best effort)” button continue the harness session of an agent in the error phase. - Workspace recreation on start (#2026): On runtimes such as Kubernetes that don’t keep workspaces across a stop, start sends the clone config needed to recreate the workspace.
- Broker quota accounting (#1951, #1967, #1975, #1978): Reservations are now released correctly across failed starts, failed creates, stop/suspend and timed-out DM wakes.
- Start and restart reliability (#1941, #1891, #1890, #1964, #1976, #1972, #1988, #1845): Skills resolve as the agent’s creator. Model aliases resolve on resume. Transient
docker psfailures are retried. Container lookup failures return 5xx instead of false success. - Leaked sandboxes on dispatch timeout (#1908): The hub cancels timed-out dispatches, and Docker, Podman and Apple container runtimes roll back any container that started.
scion project status(#1782): A new command (aliashealth) shows per-project agent metrics. (Contributor: G. Hussain Chinoy)- Agents can read skills (#1950): Agents can list and read hub-catalog skills and skills from their own project.
☁️ Deployment & Operations
Section titled “☁️ Deployment & Operations”- Binary auto-update (#1824): New maintenance config fields
deployment_tier,release_channel,update_policyandcheck_interval_hours. The check-updates API dispatches by tier. - Headless deploy (#1823, #1862):
deploy.sh --configpre-answers all prompts. The config format is now JSON, which removes the PyYAML dependency. - Hardened GCP orgs (#2004, #1980): Deploy works under common org policies using a zero-role proxy service account, and reuses or creates a subnet-scoped Cloud NAT.
- Deploy friction-log sweep (#1836, #1827, #1867): Twelve fixes from live runbook testing, plus an IAP proxy image built on the VM so deploys no longer depend on GCS.
- Hybrid tier NFS shared directories (#1849, #1877, #1889):
server.shared_dir_storagebacks shared directories with NFS for Docker and Kubernetes agents. Operations go through a confined resolver with hardened modes and ACLs, and a project’s NFS tree is removed when the project is deleted. - Agent hub endpoint override (#1925):
server.hub.agent_endpointoverrides only theSCION_HUB_ENDPOINTgiven to agents. - Profile timezone (#1822, #1884): Profiles have an IANA timezone setting, editable in web settings, which is injected into agent containers as
TZ.
🛠️ Platform & Runtime Fixes
Section titled “🛠️ Platform & Runtime Fixes”- Hub boot on fresh Postgres (#2028): A migration hook no longer aborts the transaction on a new database.
- Unwritable NFS workspaces on Kubernetes (#2027): The workspace-provision init container now runs for NFS-backed agents, so
/workspaceis writable. - Docker agent listing (#1888):
docker psrequests only the fields it parses, which avoids size-computation races that broke listing and delivery. - Doctor fixes (#1924, #1780):
sciontool doctorno longer revokes the agent’s token.scion doctorpasses stored hub auth tokens. - Default templates and harness configs (#1898, #1905): Embedded defaults load at bootstrap, so creates no longer return 502.
- Identity and rename consistency (#2019, #2014, #1920, #1919, #1917): Agent identity keys are unique per project. Agent operations work for paths recorded before the directory rename. chat-app accepts project topics again.
- Container images (#1831, #1839, #2025): core-base moves to Debian 13 with a vendored git 2.55.0.
sciontool versionreports the version and commit, and images carry the OCI revision label. - Cloud Run Instances runtime (#1817): Fixes project discovery, instance-ID length, PTY support and hub endpoint resolution.
- Postgres fixes (#1796, #1810): Broker labels and annotations migrate to jsonb, and CTE seed parameters are cast to uuid. (Contributor: sal-m2026)
🎨 Web UI
Section titled “🎨 Web UI”- Responsive header redesign (#1820, #1802, #1834): Three-tier layout (full labels, icon-only, hamburger dropdown) with a centered, labeled mode switcher.
- Project page improvements (#1860, #1835, #1833, #1865): The agents section can be expanded or collapsed. The Create Project button is restored for users with no projects. Nested scrollbars are removed.
- Toast and card fixes (#1815, #1837): Fixes a Shoelace toast removal race and long agent names overflowing cards.
🧪 CI & Testing
Section titled “🧪 CI & Testing”- SQLite hub test job (#1904, #2034): A parallel job runs the roughly 73% of
pkg/hubtests that theno_sqlitebuild never compiled. - Hub test suite fixes (#1799): Fixes 25 previously failing
pkg/hubtests. - Grove regression guards (#2000, #1948): A command-tree walk and a case-insensitive compat-literal guard fail the build on any reintroduced “grove” terms.
- deploy.sh test harness (#1977): An offline gcloud stub and test runner, wired into CI.
- Release automation (#1830, #1887, #1901): Nightly manifest updates merge through PRs with retries, and conflicted PRs show a failing mergeability check.
📖 Documentation
Section titled “📖 Documentation”- Grove removal migration guide (#1962, #1996): A reference page mapping every removed grove name to its replacement.
- Agent deployment runbook (#1825, #1866, #1851): An agent-oriented runbook for the single-node VM tier covering GCP preflight, conversational prompts, config generation and troubleshooting.
- Grove wording cleanup (#1922): READMEs, CLI help and schema descriptions now say “project” instead of “grove”.
- chat-app slash commands (#1952): The README now lists admin commands under
/scionAdmin.